All skills
hardw00t avatar

/sca-security

@f9bb3b2

Software Composition Analysis: find vulnerable dependencies, correlate CVE/GHSA/OSV across ecosystems, generate CycloneDX/SPDX SBOMs, assess license compliance, and run reachability-aware triage to suppress unexploitable findings. Use when scanning package dependencies (npm, PyPI, Maven, Cargo, Go, RubyGems, Composer), reviewing PR lockfile diffs, generating SBOMs, auditing licenses, hunting malicious packages, or auditing the software supply chain. Triggers on requests to scan dependencies, check vulnerable packages, generate SBOM, license compliance, typosquat/dependency-confusion review, or reachability-based vuln triage.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/sca-security

This session only. Nothing lands on disk.

referencesruby_gems.md

≈622 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Ruby / Bundler Reference

Manifest + lockfile files

File Purpose
Gemfile manifest
Gemfile.lock lockfile
gemspec library manifest
.bundle/config bundler config

SBOM generation

# CycloneDX Ruby plugin
gem install cyclonedx-ruby
cyclonedx-ruby -p . -o sbom.cdx.json

# Syft
syft dir:. -o cyclonedx-json=sbom.cdx.json

Vulnerability scanning

# bundler-audit (RubySec Advisory DB)
gem install bundler-audit
bundle-audit check
bundle-audit check --update             # refresh advisory DB first
bundle-audit check --format json

# OSV-Scanner
osv-scanner --lockfile=Gemfile.lock

# Snyk
snyk test --file=Gemfile.lock

Dependency inspection

bundle show                          # flat list
bundle show <gem>                    # location of gem
bundle info <gem>                    # version + deps
bundle outdated
bundle outdated --strict             # respect Gemfile constraints

# Reverse dep
gem dependency <gem> --reverse-dependencies --pipe

License extraction

gem install license_finder
license_finder
license_finder report --format=json > licenses.json
license_finder approvals add 'MIT' 'Apache-2.0' 'BSD-3-Clause'

Common vulnerability patterns

Class Example DB
YAML deserialization CVE-2013-0156 (rails) RubySec
Regex ReDoS various RubySec
Rails RCE many historical RubySec
Nokogiri (libxml2) XXE CVE-2024-34459 both RubySec + NVD
Rack / request smuggling CVE-2024-26146 RubySec

Gotchas

  • Gems can ship C extensions (ext/) built at install time via extconf.rb — arbitrary code execution at install, like npm postinstall.
  • Gemfile allows gem 'foo', git: 'https://...' — git sources bypass rubygems.org supply chain controls. Audit.
  • Native gems (precompiled per platform) have per-platform gemspec files — SBOM tools sometimes miss the correct platform.
  • Bundler's --deployment mode pins to Gemfile.lock strictly — use in CI for reproducibility.

Supply chain checks

# Bundler signature verification (opt-in)
bundle config set --global trust-policy HighSecurity
# Requires all gems to be signed; most aren't in practice.

# Check gem metadata
gem info <gem> --remote
# Look at: authors, owners, homepage, download count

Tool minimums (2026-04)

  • bundler >= 2.5
  • bundler-audit >= 0.9.2
  • ruby >= 3.2
  • license_finder >= 7.2

Source: SKILL.md on GitHub

1 warning16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    A highly comprehensive and professional Software Composition Analysis (SCA) skill designed for auditing dependencies, generating SBOMs, and detecting supply chain attacks. The skill correctly identifies and provides detection workflows for sophisticated attack vectors such as typosquatting, dependency confusion, and malicious install scripts. No malicious patterns or security risks were detected in the skill's own operation.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: MEDIUM · 1 issue

  • Runlayer7mo

    1/1 file flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/sca-security